Ãë¾àÁ¡ID |
22147 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Apache À¥¼¹ö´Â WebDAV¸¦ ÅëÇÑ µð·ºÅ丮 ¸®½ºÆÃ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. WebDAV (Web Distributed Authoring and Versioning)´Â »ç¿ëÀÚµéÀÌ HTTP ÇÁ·ÎÅäÄÝÀ» ÀÌ¿ëÇÏ¿© ¹®¼µéÀ» »ý¼º, ÆíÁý, °øÀ¯ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â HTTPÀÇ ºÎ°¡±â´É(extension) ÀÌ´Ù. Ưº°ÇÑ REQUEST METHODÀÎ PROPFIND´Â »ç¿ëÀÚµéÀÌ µð½ºÇ÷¹ÀÌ ¸í, ¸¶Áö¸· ¼öÁ¤µÈ ³¯Â¥ µî°ú °°Àº ÀÚ¿ø¿¡ °üÇÑ Á¤º¸¸¦ °Ë»öÇØ º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. SuSE 6.4¿¡ µðÆúÆ®·Î ¼³Ä¡µÈ Apache À¥¼¹ö´Â ¼¹öÀÇ Àüü ÆÄÀÏ ±¸Á¶¸¦ ´ë»óÀ¸·Î ÇÏ´Â WebDAV¸¦ °¡Áö°í ÀÖ´Ù. Apache À¥¼¹ö·Î Ưº°ÇÏ°Ô ¸¸µé¾îÁø ¿äûÀ» º¸³¿À¸·Î½á µð·ºÅ丮 ¸®½ºÆÃ Á¤º¸¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/1656 http://www.iss.net/security_center/static/5204.php
* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû: Apache HTTP ¼¹ö ¸ðµç ¹öÀü SuSE Linux ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
WebDAV ¸ðµâÀ» ÀÛµ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù. ÀÛµ¿ÁßÁö ½Ã۱â À§Çؼ´Â:
1. WebDAV·Î ¿ÀÇÂÇØ ³õ°íÀÚ ÇÏ´Â °¢°¢ÀÇ µð·ºÅ丮¿¡ ´ëÇØ httpd.conf¿¡ ÀÖ´Â ´ÙÀ½ ¿£Æ®¸®µéÀ» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù:
<Directory /webdav/directory/goes/here> #add other directives as needed such as Order allow,deny <IfDefine DAV> DAV On </IfDefine> </Directory>
Apache¸¦ ÁßÁöÇϰí Àç½ÃÀÛÇÑ´Ù.
2. WebDAV¸¦ ¿ÏÀüÈ÷ ÀÛµ¿ÁßÁö ½Ã۱â À§Çؼ´Â httpd.conf¿¡¼ ´ÙÀ½ ¿£Æ®¸®µéÀ» ¿ì¼± ã´Â´Ù:
<IfDefine DAV> DAV On </IfDefine>
±×¸®°í "On"À» "Off"·Î ¹Ù²Û´Ù. µðÆúÆ®·Î´Â "/usr/local/httpd/htdocs" ¸¸ÀÌ IfDefine DAV Áö½ÃÀÚ¸¦ °¡Áø À¯ÀÏÇÑ µð·ºÅ丮ÀÌ´Ù. ¶ÇÇÑ ÀÌ Áö½ÃÀÚ¸¦ °¡Áø ´Ù¸¥ µð·ºÅ丮µéÀÌ ÀÖ´Ù¸é ¸¶Âù°¡Áö·Î ¹Ù²Ù¾î¾ß ÇÑ´Ù.
Apache¸¦ ÁßÁöÇϰí Àç½ÃÀÛÇÑ´Ù.
3. WebDAV ¸ðµâ¾øÀÌ Apache¸¦ Àç½ÃÀÛ½Ã۱â À§Çؼ´Â /etc/rc.d/rc3.d/S20apache ÆÄÀÏÀ» ÆíÁýÇÏ¿© ´ÙÀ½ ¶óÀÎÀ» ÁÖ¼®Ã³¸®("#") ÇØ¾ß ÇÑ´Ù:
test -e /usr/lib/apache/libdav.so && MODULES="-D DAV $MODULES"
´ÙÀ½¹ø Apache ½ÃÀÛ ½Ã¿¡ ÀÌ ¸ðµâÀº Æ÷ÇÔµÇÁö ¾ÊÀ» °ÍÀÌ´Ù.
-- ¶Ç´Â --
SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE º¸¾È°ü·Ã °øÁö¸¦ ÂüÁ¶ÇÏ¿© ApacheÀÇ ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://online.securityfocus.com/advisories/2609 |
°ü·Ã URL |
CVE-2000-0869 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|